Seller Impersonation Fraud Is Evolving. Is the Mortgage Industry Evolving Fast Enough?
AI and increasingly sophisticated wire fraud are raising the stakes at the closing table, forcing lenders to rethink how they verify identities, counterparties, and payment instructions
For years, the mortgage industry has spent a lot of money on spotting borrower fraud at the start of the loan process. But one of the growing fraud threats today may show up later — when the loan is approved, the closing is set, and hundreds of thousands of dollars are about to move.
Seller impersonation fraud, business email compromise, and wire-diversion schemes are coming together into a closing-table threat. AI is making that threat more sophisticated.
The Numbers Are Getting Harder To Ignore
The FBI’s Internet Crime Complaint Center reported $20.9 billion in internet-crime losses in 2025, a 26% increase from 2024. Business email compromise alone accounted for $3 billion in reported losses during the year.
The FBI has described business email compromise as a “$55 billion scam,” calculating more than $55.4 billion in exposed losses from domestic and international incidents reported between October 2013 and December 2023.
For mortgage lenders, the message is clear: the closing table has become a cybersecurity perimeter.
Seller Impersonation Is Accelerating
Seller impersonation fraud generally involves a criminal pretending to be the owner of a property and trying to sell or otherwise transact against property the criminal does not own.
The American Land Title Association’s latest research shows how quickly the problem is evolving.
ALTA’s 2026 Seller Impersonation Fraud Study, based on responses from 245 title professionals in 40 states, the District of Columbia, and the U.S. Virgin Islands, found that 59% of firms had at least one seller impersonation attempt in 2025. That is more than double the 28% reported in ALTA’s earlier study.
More concerning, 45% reported an attempt in the month before the survey, compared with 19% in earlier research. Among firms that reported a fraud attempt, one in four also reported a paid claim linked to seller impersonation. Of those that disclosed claim costs, half reported costs above $100,000.
MBA NewsLink previously highlighted the earlier ALTA findings that 28% of title companies had at least one seller impersonation attempt in 2023.
This means lenders should not see seller impersonation as a title company problem. If a fraudulent seller reaches closing, the lender, settlement agent, title insurer, warehouse provider, and consumer can all be part of — and potentially victims of — the compromised transaction.
AI Changes The Economics Of Fraud
Artificial intelligence adds another dimension.
The old warning signs of fraud — a poorly written email, awkward grammar, a questionable identification document, or an implausible explanation — are becoming less reliable.
Generative AI can help criminals produce letters, imitate professional communications, and quickly create transaction-specific stories. Synthetic images, altered documents, AI-generated voices, and advanced video technology mean that a phone call or video conference should not automatically be treated as proof of identity.
Criminals can gather available property and personal information, create a convincing identity profile, and communicate with transaction participants in a way that looks increasingly legitimate.
The industry’s response cannot simply be, “We spoke to the seller.”
The better question is: What independent data confirms that the person we spoke with is actually the property owner?
Business Email Compromise Remains The Gateway
AI may be changing fraud. One of the industry’s most persistent weaknesses remains familiar: email.
FinCEN describes business email compromise schemes as attacks against organizations that routinely conduct wire transfers and rely on email. In real estate, criminals may compromise — or convincingly impersonate — trusted parties and then change payment instructions.
FinCEN’s analysis of real-estate business email compromise found that the most common victims were people and entities involved in the title and closing process. Eighty-eight percent of incidents initially sent fraudulent payments to accounts at U.S. depository institutions, showing that employees cannot assume a domestic bank account makes instructions legitimate.
The FBI has also documented the real-estate connection. From 2020 to 2022, reports of business email compromise incidents with a real estate link rose 27%, while reported losses rose 72%. Reported losses reached about $446 million in 2022.
The MBA has also been sounding the alarm. At the 2025 Compliance and Risk Management Conference, representatives from law enforcement discussed the mortgage industry’s exposure to fraud. An FBI supervisory special agent highlighted BEC targeting home closings, where victims are tricked into wiring transaction funds to criminals.
Employee Training Is Part Of The Defense
Technology matters. But lenders should not think technology alone can stop these attacks.
Criminals often exploit behavior instead of breaking security systems. They create urgency. They impersonate parties. They slip into email conversations. They wait until closing, when employees feel pressure to get the transaction funded.
That turns employee training into an operational issue, not just a cybersecurity exercise.
Funding, closing, post-closing, accounting, warehouse, servicing, and vendor-management personnel should learn to spot red flags, including changes to wire instructions, slightly altered email domains, changes in beneficiary names or banks, unusual urgency, requests to skip normal procedures, and instructions to use a new telephone number or email address.
One rule must be very clear:
Wire instructions should never be changed only because an email says they have changed.
The FBI recommends using a secondary communication channel or two-factor authentication to verify changes in account information.
Verification should happen through an independently verified communication channel — not the telephone number, link, or email address that appears in the message asking for the change.
Verification Needs To Go Deeper
The industry must go beyond identity verification and move toward identity, counterparty and transaction verification.
That means checking the seller’s relationship to the property, validating settlement professionals, checking bank-account data, spotting transaction anomalies, authenticating changes to wire instructions, and establishing escalation procedures that allow employees to halt transactions before funds leave the institution.
ALTA’s latest research backs that layered approach. Ninety-four percent of firms that responded used fraud-detection tools they found helpful, averaging 5.3 tools per firm. Identity verification, direct seller contact, and multifactor authentication were among the highly rated defenses.
There is another lesson in the government’s recovery statistics: Speed matters after a fraudulent wire is discovered.
FinCEN said in April 2026 that its Rapid Response Program had facilitated the interdiction of more than $1.8 billion in stolen funds since the program began, including about $425.2 million linked to business email compromise. FinCEN stresses the need to report cyber-enabled fraud quickly to law enforcement so authorities have a chance to freeze or recover stolen funds.
Recovery Is The Last Line Of Defense
The better strategy is to stop the wire from being misdirected in the first place.
Mortgage lenders have spent decades building systems to decide whether a borrower, property, and loan are acceptable for credit and collateral risk. The next step is to apply that same discipline to the people, companies, and payment instructions surrounding the closing.
Because in an AI-enabled fraud world, seeing a driver’s license is not enough. Getting an email is not enough. Hearing a voice is not enough. And increasingly, even seeing someone on a screen may not be enough.
Trust at the closing table must come from verified data.
For mortgage lenders, that quickly becomes the difference between completing a transaction and financing a fraud.
Sources: FBI Internet Crime Complaint Center, 2025 IC3 Annual Report and BEC public-service advisories; Financial Crimes Enforcement Network, Business Email Compromise in the Real Estate Sector and Rapid Response Program data; American Land Title Association, 2026 Seller Impersonation Fraud Study; and Mortgage Bankers Association/MBA NewsLink industry reporting.